On 26 August 2026, Meta filed a proposed Consent Judgment with the Federal Court overseeing In re: Social Media Adolescent Addiction/Personal Injury Products Liability Litigation (N.D. Cal.), settling claims brought by dozens of state Attorneys General that accuses Facebook and Instagram to addict children and mislead the public about the risks. The company -as reported by mainstream press- will pay up to roughly $17–18 billion over ten years, restrict teen accounts to daily time limits and overnight blackouts, roll out "enhanced" age-checking, and expand parental controls. Meta admits no wrongdoing.
California's Attorney General called it a settlement that will "make a world of a difference for children and their families." But a close read of the 130-page agreement suggests a more modest verdict: this is a real, useful step — and also a carefully engineered one, built to look far more binding than it is once you follow the timelines and the oversight mechanics to where they actually lead.
What Meta is actually promising
Stripped to its structure, the settlement asks Meta to do seven things for teen (13–17) and under-13 users across its platforms: 1) build a general age-assurance system; 2) cap and interrupt night-time and daily use; 3) offer a non-algorithmic feed option; 4) hide like counts and ban "cosmetic filter" effects; 5) keep existing content-safety measures in place while improving them; 6) keep existing anti-predator measures in place while improving them; and 8) give parents more visibility and control.
All of this is real, and none of it is nothing — hiding engagement metrics and forcing overnight blackouts are exactly the sort of low-cost, high-leverage interface changes that safety-by-design researchers, including the author of the present blogpost, have called for.
The trouble starts when you ask two questions any settlement of this kind should answer: when, exactly, and checked by whom?
The timeline problem: Phase I is not Phase II
The most-quoted number in press coverage — a 60-minute daily cap per app, capped at two hours across apps, and a 10 p.m.–7 a.m. blackout — is not what takes effect first. It is "Phase II," and Phase II is contingent. The looser "Phase I" defaults (a midnight–6 a.m. blackout, and a softer usage cap -e.g. 120 minutes of usage between Facebook and Instagram combined) apply for up to five years. The stricter (60 min cap for each App) Phase II regime only switches on if "Industry-Wide Adoption" occurs — a defined threshold requiring that Snap, TikTok, and YouTube (the agreement's "Core Industry Members") also adopt comparable restrictions, within a ten-year window that starts running from the settlement's effective date, not from today.
In other words, Meta's strongest commitments are not obligations in the ordinary sense; they are options that vest only if competitors move first — competitors who are not parties to this agreement and face no comparable deadline to do so. "Core Industry Members," in the agreement's defined terms, means Snap, TikTok, and YouTube specifically — none of which is a party to this settlement or under any obligation, contractual or otherwise, arising from it.
The same contingency structure governs part of the money. Exhibit B show ten annual "Guaranteed Installment Payments" totalling roughly $11.66 billion over the ten-year term — unconditional, alongside the $75 million Cost Fund payment and the $459.29 million Cambridge Analytica component, also both unconditional. Separately, ten annual "Contingency Installment Payments," totalling a further $5.02 billion at maximum, are paid only if a defined "Contingent Monetary Payment Trigger" occurs: broadly, once all three named competitors have adopted legally binding equivalents of Meta's strictest ("Phase II") time-limit obligations and face comparable monetary exposure of their own. That is roughly 30% of the states' aggregate settlement fund — around $5 of every $16.7 billion in the injunctive-relief pool the Exhibit B table totals — sitting on a trigger Meta does not control and three non-party companies have no obligation under this agreement to comply with. If the trigger never fires in a given state, that state forfeits its Contingency Installments permanently, and Meta owes nothing in their place.
The oversight problem: audited by whom, enforced how?
The accountability architecture built into Section III of the agreement is genuinely more developed than in many prior tech settlements — there is a jointly-selected Independent Auditor, a defined scope of work, a right of access to Meta's data and personnel, and a formal reporting cycle. It is worth taking seriously as a template. It is also worth reading past the label "independent."
Three structural features are worth considering: First, the Auditor is paid by Meta, and the agreement gives Meta a formal process to challenge the Auditor's costs as "excessive”. Second, the Auditor's findings are, for the most part, confidential: only a public executive summary is released, Meta gets to review and comment on that summary before publication, and Meta may designate underlying material "Confidential" with contractual notice rights before any of it can be disclosed. Third, and most important, where the Auditor identifies a "material gap or weakness," it is Meta that drafts the corrective action plan; the Auditor's role is limited to approving or commenting on Meta's own proposal within 90 days. Several of the agreement's provisions — the productive-pause redesign, the soft-matching improvements, the U13 detection targets — are qualified as non-binding recommendations even at the point the Auditor delivers them.
There is, moreover, no schedule of fines or automatic penalties for non-compliance anywhere in the injunctive sections. Disputes go through a mandatory "meet and confer" process, and only then, potentially, to the court that retains jurisdiction over the judgment. That is a normal feature of consent decrees — but it means enforcement, in practice, depends on the same states' Attorneys General noticing a violation, building a record, and being willing to litigate it years down the line. Not the most effective implementation device, of course, but then again, this is the advantage (for the company) to have a settlement instead of a ruling.
Age assurance: the technology gap was never the real gap
Much of the settlement's credibility rests on its age-assurance provisions: annual third-party testing, defined false-positive thresholds, a "U13 Age Model", soft-matching to catch secondary accounts. These are more specific than most prior commitments in this space, and the false-positive targets are not trivial to hit.
But it is worth being precise about what problem this actually solves, and what it does not. As my forthcoming paper on the copyright and platform-liability dimensions of minors' presence on social media argues, the empirical evidence — including research showing that recommendation algorithms on YouTube, Instagram, and TikTok already adapt to signals associated with underage accounts — indicates that platforms have long possessed the inferential capability to identify likely-minor users without formal identity verification.¹ The obstacle to age assurance, on this account, was never primarily technical; it was that platforms had commercial reasons not to deploy that capability protectively. Read against that argument, the settlement's Age Assurance Framework looks less like a technological breakthrough Meta had to build from scratch, and more like a legal requirement to redirect a capability that, as the evidence suggests, substantially existed already — with the settlement's real contribution being certification and reporting obligations around it, rather than the underlying detection method itself.²
A step, not a verdict
None of this is an argument that the settlement is worthless, or that the states negotiated badly. $17–18 billion, a default overnight blackout, hidden like-counts, and a public reporting mechanism — however diluted — are more than teen users of Facebook and Instagram had a week ago, and more than a court judgment might plausibly have delivered on this timeline. The California Attorney General's claim that the relief goes "well beyond what any court has ordered or is likely to order" is not entirely wrong.
But "more than before" and "a victory" are different claims. A victory would look like binding, near-term obligations, verified by a genuinely independent auditor with public findings and real consequences for non-compliance. What the settlement actually delivers is a layered structure in which the strongest protections are optional and contingent on competitors, the audit function is self-funded and largely confidential, remediation is self-directed, and enforcement runs through years of potential litigation rather than automatic penalties.
Overall, this is a step forward, useful and overdue, in the direction of taking platform design seriously as a source of harm to minors — and, at the same time, a settlement whose architecture ensures that whether it becomes anything more than that will be decided later, largely out of public view, and largely by Meta itself.
Summing up, a fair characterisation of the settlement is: guaranteed weaker protections now, the possibility of stronger protections later - contingent on an industry-wide race that this settlement does not compel anyone else to run. However, separate litigation is under way against the other “Core Industry Members” which may -hopefully- lead all of them to converge towards much needed child protection Industry Standards.
¹ See M. Hilbert et al., "#BigTech @Minors: Social Media Algorithms Have Actionable Knowledge about Child Users and At-Risk Teens," Telematics and Informatics 103 (2025).
² For the fuller argument — including on the copyright, contractual-capacity, and platform-liability incoherence that age-assurance and access-restriction measures do not resolve — see Marcella Favale, "The Liability Paradox: Copyright Ownership, Contractual Incapacity, and Platform Exploitation of Minor Creators under the DSM Directive and DSA" (forthcoming, International Journal of Law and Information Technology), preprint available at SSRN, and the accompanying discussion, "The Liability Paradox: Why Social Media Bans Miss the Point".
Add comment
Comments